Hi Experts,
I'm planning to migrate another vendor firewall to checkpoint (R81.10 Take 66) and have a query relating to IPS/Inspection settings for SIP traffic.
Option1:-
Source: SIP Server
Destination: SIP Phone
Ports: sip_tls_authentication , sip, udp-high-ports (With Protocol defined)
Action: Allow
Option 2:-
Source: SIP Server
Destination: SIP Phone
Ports: sip_tls_not_inspected , TCP/5060 (with protocol NONE), udp-high-ports
Action: Allow
Can someone please suggest the best option in configuring IPS inspection for SIP traffic to avoid drops or one-way calls?
Thanks in advance.